Junglewise Threat Intelligence

CVE-2026-23431: Linux Kernel Amlogic SPISG memory leak in aml_spisg_probe

CVE-2026-23431 · Severity: medium · CVSS 5.5 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Amlogic SPI driver could allow a local user to cause a memory leak. This occurs when the system fails to properly initialize the hardware driver, leading to the gradual consumption of system memory. Over time, this could result in system instability or a complete crash, affecting the availability of services running on the device.

Technical details

A memory leak exists in the aml_spisg_probe() function of the drivers/spi/spi-amlogic-spisg.c component in the Linux kernel. The vulnerability is caused by a failure to call spi_controller_put() in several error handling paths after the controller (ctlr) has been allocated via spi_alloc_target() or spi_alloc_host(). An attacker with local access could potentially trigger repeated probe failures to exhaust system memory. The issue has been resolved by converting the allocation to use managed device functions (devm_spi_alloc_host/devm_spi_alloc_target), which ensure memory is automatically freed upon probe failure.

Affected products

  • Linux Linux Kernel 6.17 to 6.18.20, 6.19 to 6.19.10

Timeline

  • 2026-04-03: disclosed: Initial publication of the CVE
  • 2026-03-15: patched: Fix committed to the Linux kernel tree

References

Related threats